We performed a comparison between OWASP Zap and Rapid7 AppSpider based on real PeerSpot user reviews.
Find out in this report how the two Static Application Security Testing (SAST) solutions compare in terms of features, pricing, service and support, easy of deployment, and ROI."You can run it against multiple targets."
"It scans while you navigate, then you can save the requests performed and work with them later."
"It's great that we can use it with Portswigger Burp."
"It can be used effectively for internal auditing."
"The solution is good at reporting the vulnerabilities of the application."
"The solution is scalable."
"The application scanning feature is the most valuable feature."
"Automatic updates and pull request analysis."
"It scans all the components developed within a web application."
"The initial deployment is very straightforward and simple. The product is stable if configured properly."
"Rapid7 AppSpider is good at managing different applications. It uses applets and generates reports to cover the PCA/GDPR compliance requirements."
"I like the ability the product has to detect vulnerabilities quickly, when it has been released in our environment, then displaying them to us."
"The most valuable feature of Rapid7 AppSpider is the vulnerability reporting data. Additionally, the data is reported in a convenient way rather than seeing them as a PDF. We are able to generate all the reports exactly what we want in a flexible way."
"What I like most about AppSpider is that it's easy to use and its automated scan gives me all the details I need to know when it comes to vulnerabilities and their solutions."
"It is really accurate and the rate of false positives is very low."
"When it is set up properly, it can do scanning on web apps with multiple engines automatically."
"The solution is somewhat unreliable because after we get the finding, we have to manually verify each of its findings to see whether it's a false positive or a true finding, and it takes time."
"They stopped their support for a short period. They've recently started to come back again. In the early days, support was much better."
"If there was an easier to understand exactly what has been checked and what has not been checked, it would make this solution better. We have to trust that it has checked all known vulnerabilities but it's a bit hard to see after the scanning."
"The product should allow users to customize the report based on their needs."
"The port scanner is a little too slow."
"It needs more robust reporting tools."
"Deployment is somewhat complicated."
"It doesn't run on absolutely every operating system."
"There are some glitches with stability, and it is an area for improvement."
"Support response times are slow and can be improved."
"Implementing Rapid7 AppSpider requires scanning and self-identification mechanisms. You can add different types of authentication to each scan."
"AppSpider could improve in the area of integration. They need to add more integration opportunities."
"This price of this solution is a little bit expensive."
"The dashboard and interface are crucial and they need some improvement."
"Integration could be better."
"One of the challenges I have with AppSpider is that it gives you a lot of false positives, especially when compared to other solutions."
OWASP Zap is ranked 8th in Static Application Security Testing (SAST) with 37 reviews while Rapid7 AppSpider is ranked 26th in Static Application Security Testing (SAST) with 13 reviews. OWASP Zap is rated 7.6, while Rapid7 AppSpider is rated 7.8. The top reviewer of OWASP Zap writes "Great for automating and testing and has tightened our security ". On the other hand, the top reviewer of Rapid7 AppSpider writes "Useful vulnerability reporting data, flexible, and simple implementation". OWASP Zap is most compared with SonarQube, Acunetix, Qualys Web Application Scanning, Veracode and GitLab, whereas Rapid7 AppSpider is most compared with Rapid7 InsightAppSec, Acunetix, Invicti, Qualys Web Application Scanning and Tenable.io Web Application Scanning. See our OWASP Zap vs. Rapid7 AppSpider report.
See our list of best Static Application Security Testing (SAST) vendors.
We monitor all Static Application Security Testing (SAST) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.